Daily briefing · July 5, 2026

cve-search Critical Flaw Leads July 5 Roundup Alongside Multiple PoC-Exposed Vulnerabilities

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

July 5, 2026 brought 84 new vulnerabilities, with one critical disclosure standing out: an unauthenticated input validation flaw in cve-search that could expose administrative credentials directly from MongoDB. The day saw no active KEV exploitation, but six of the ten highlighted CVEs carry public proof-of-concept code, significantly narrowing the window between disclosure and real-world abuse. Several entries target Turkish public-sector software from TUBITAK BILGEM, broadening the geographic scope of concern.

Today’s brief
  • CRITICAL: CVE-2026-59509 in cve-search allows unauthenticated attackers to read MongoDB collections, including admin password hashes — patch or isolate immediately.
  • Six of ten highlighted CVEs have public PoC exploits, meaning weaponization is already within reach of low-skilled attackers.
  • Multiple TUBITAK BILGEM products (Pardus suite, Domain Joiner) are affected by privilege escalation, DNS spoofing, and credential exposure flaws.
  • Network devices and web applications (UTT HiPER router, Ruijie RG-UAC, WeChat bot) round out a diverse and practically exploitable set of targets.
1
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-59509CVSS 9.2PoCaffects cve-search
An unauthenticated attacker can manipulate POST parameters on the /fetch_cve_data endpoint to query arbitrary MongoDB collections in cve-search, including the mgmt_users collection containing admin usernames and password hashes. With a public PoC already available, any exposed instance should be treated as compromised until patched or isolated.
2
CVE-2026-9085HIGH 8.8affects Pardus-Parental-Control
Incorrect permission assignment in Pardus-Parental-Control (versions up to 0.5.1) allows attackers to perform DNS spoofing, potentially redirecting users to malicious infrastructure. Organizations running this parental control solution on Turkish Pardus Linux deployments should upgrade to 0.7.0 or later without delay.
3
CVE-2026-14721HIGH 8.7PoCaffects HiPER 1250GW
A stack-based buffer overflow in the UTT HiPER 1250GW router's web endpoint (via the ssid argument) can be triggered remotely, and a public exploit has already been disclosed. Routers exposed to the internet or untrusted networks are at direct risk of remote code execution.
4
CVE-2026-12250HIGH 7.9affects Pardus Domain Joiner
Pardus Domain Joiner (before 0.5.4) exposes sensitive credentials through process invocation in a way visible to local observers, enabling credential excavation by low-privileged users. Systems joined to domains using this tool should be updated and credentials rotated as a precaution.
5
CVE-2026-6509HIGH 7.8affects Pardus Update
A missing authorization check in Pardus Update (before 0.6.6) can be leveraged for local privilege escalation, allowing an attacker with limited access to gain elevated system rights. This is especially concerning in multi-user or shared environments running the Pardus Linux distribution.
6
CVE-2026-59510HIGH 7.1affects ail-framework
A path traversal vulnerability in AIL Framework's PDF object handling allows authenticated users to read files outside the intended PDF storage directory. Defenders should apply the fix from commit 14c618fce4d1df02358717c48ea903706abecdf2 and audit file access logs for anomalous path patterns.
7
CVE-2026-14714MEDIUM 6.9PoCaffects chatgpt-on-wechat CowAgent
Missing authentication on the wx endpoint's verify_server function in chatgpt-on-wechat CowAgent 2.1.0 allows remote attackers to interact with the WeChat integration without credentials, with a public PoC already available. Instances exposed to the internet should be upgraded or placed behind authentication controls immediately.
8
CVE-2026-14736MEDIUM 6.9PoCaffects RG-UAC
An unrestricted file upload vulnerability in Ruijie RG-UAC's user_auth_commit.php allows remote attackers to upload arbitrary files, a classic vector for webshell deployment and full system compromise. The public exploit makes this an urgent patching priority for any organization using this unified access controller.
9
CVE-2026-14735MEDIUM 6.9PoCaffects Smart Parking System
SQL injection via the street, city, and status parameters in the Smart Parking System 1.0 (/parkings/parkings.php) can be exploited remotely to extract or manipulate the underlying database. A public exploit is available, making any publicly accessible deployment an easy target for data theft.
10
CVE-2026-14734MEDIUM 6.9PoCaffects Class and Exam Timetabling System
A SQL injection flaw in SourceCodester Class and Exam Timetabling System 1.0 (/edit_product.php) via the ID parameter allows remote attackers to interact with the backend database. With a published exploit, educational institutions running this system should restrict access and apply available patches immediately.
Today’s recommendation: Prioritize patching or network-isolating CVE-2026-59509 in any cve-search deployment, as unauthenticated credential theft poses an immediate takeover risk; simultaneously audit all PoC-exposed entries (especially CVE-2026-14721, CVE-2026-14736, and CVE-2026-14735) and apply vendor updates or compensating controls before attackers operationalize the available exploits.
With six public exploits disclosed in a single day spanning routers, web apps, and platform tools, now is the right moment to validate which of these affected components actually exist in your environment and confirm your detection coverage can catch exploitation attempts.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →